PT-2026-50786 · Libssh2+3 · Libssh2+3
CVSS v4.0
8.3
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
libssh2 versions prior to 1.11.1 commit 2dae302
Description
An out-of-bounds heap read exists in the
sftp symlink() function within src/sftp.c. A malicious SSH server or man-in-the-middle attacker can disclose heap memory contents or cause a crash by sending a crafted SSH FXP NAME response. This occurs because the software fails to validate the available packet buffer size before a memcpy operation, allowing an attacker to supply a link len value larger than the actual packet data during SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target len minus one bytes.Recommendations
Update to the version containing commit 2dae302 to resolve the issue.
Exploit
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Libssh2